Input validation error in DataEase - CVE-2026-53751
Published: June 18, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in the JDBC URL validation logic for H2 database connections when handling a crafted H2 JDBC connection string. A remote user can send a specially crafted request containing Unicode-altered blacklisted parameters to execute arbitrary code.
Exploitation requires a valid DE token.